Description
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
Published: 2021-03-26
Score: 6.1 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-26613 Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
History

No history.

Subscriptions

Tp-link Archer-c3150 Archer-c3150 Firmware Td-w9977 Td-w9977 Firmware Tl-wa801n Tl-wa801n Firmware Tl-wa801nd Tl-wa801nd Firmware Tl-wr802n Tl-wr802n Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T16:53:17.136Z

Reserved: 2021-01-22T00:00:00.000Z

Link: CVE-2021-3275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-26T13:15:11.663

Modified: 2024-11-21T06:21:11.943

Link: CVE-2021-3275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses